Lucene search

K
certCERTVU:817940
HistorySep 05, 2008 - 12:00 a.m.

NetBSD malformed ICMPv6 MLD-QUERY denial of service

2008-09-0500:00:00
www.kb.cert.org
14

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

0.012 Low

EPSS

Percentile

85.6%

Overview

NetBSD fails to properly handle ICMPv6 MLD query packets, which can allow a remote, unauthenticated attacker to cause a denial of service.

Description

ICMPv6, which is defined in RFC 4443, is a version of the ICMP protocol for IPv6. Multicast Listener Discovery (MLD) for IPv6, which is defined in RFC 2710, uses ICMPv6 message types. MLD is used to discover the presence of multicast listeners on a router’s directly attached links. MLD messages are sent with a link-local IPv6 source and a hop limit of one, which restricts the traffic to the local link. NetBSD fails to properly handle an ICMPv6 MLD-QUERY packet that has a Maximum-Response-Delay field set to the value of less than 0x0010. Upon receiving such a packet, code in the NetBSD kernel will attempt a division by zero and the system will stop.


Impact

An attacker on a local link can cause a NetBSD system to crash, resulting in a denial-of-service condition.


Solution

Apply an update

This issue is addressed in NetBSD Security Advisory 2008-011.


Vendor Information

817940

Filter by status: All Affected Not Affected Unknown

Filter by content: __ Additional information available

__ Sort by: Status Alphabetical

Expand all

Javascript is disabled. Click here to view vendors.

NetBSD __ Affected

Updated: September 05, 2008

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

This issue is addressed in NetBSD Security Advisory 2008-011.

If you have feedback, comments, or additional information about this vulnerability, please send us [email](<mailto:[email protected]?Subject=VU%23817940 Feedback>).

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to CERT-FI Vulnerability Coordination for reporting this vulnerability, who in turn credit Codenomicon.

This document was written by Will Dormann.

Other Information

CVE IDs: CVE-2008-2464
Severity Metric: 3.12 Date Public:

7.1 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

0.012 Low

EPSS

Percentile

85.6%

Related for VU:817940